An article on the relative security and insecurity of websites and banks
Why is it that websites deem a 6 character all lower case password to be "very weak" when there's 306million+ possibilities. Yet a 4 digit PIN (9999 possibilities) is secure enough for banks?
The website one is almost 31,000 times more secure yet is deemed "weak". Surely a rule for websites that if the incorrect password is used a certain number of times the account is locked would be sufficient to make the weak password 31,000 times stronger than the bank's security.
We have to be practical about this. In reality, any rules around requiring a password to have upper and lower case letter and special characters such as $,% etc simply make it much more likely people will write the passwords down. Just because this makes it the person's problem rather than the website's is no excuse - the overall security of the account is the issue, including the likelyhood that the account will be broken into because the password was so complicated it, together with the dozons of other passwords from other sites, all had to be written down somewhere because it was too much to remember.
Can we please have simpler password rules for websites and some way of having one strong security mechanism which ties them all together?
Craig
By Craig Cockburn, IT Professional from Scotland. Digital Transformation, Agile Management, Politics and Social change
Total Pageviews
Subscribe to:
Post Comments (Atom)
Popular Posts
-
An article on how Agile can sit alongside PRINCE2 and where DSDM Atern fits in. In 2007, I put "used an Agile/PRINCE2 development str...
-
Having been on hold to the Orange contact centre (I guess that's what you would call it, I might call it a non-contact centre) for appro...
-
All In the last few months, I have seen the traffic to this blog rise to a reasonable level and there's been a lot of diverse comments a...
-
In a breathtaking act of complete user ignorance, the so called new user experience of Windows Vista is now significantly harder to shut dow...
-
Another idea for Cambrian House YouTube for the road. When we were on Skye recently, we shot a video from the car, and it's really inter...
-
Find me on LinkedIn https://www.linkedin.com/in/siliconglen/ Medium https://siliconglen.medium.com/ thanks Craig
-
Your profile indicates you have been contracting recently, therefore you will only be interested in contract work then? Incorrect. Thi...
-
Trying a bit of reverse marketing here to see whether posting to Google Groups: uk.jobs.wanted and also to Ebay.co.uk in an unconventional...
-
BBC displays another example of the Scunthorpe problem . I am no longer allowed to use my name on the BBC site. See the screendump (click to...
-
On 1st October 2006, the UK enacted a law to make ageism illegal . This is only for employment but nonetheless, despite privacy concerns, ma...
No comments:
Post a Comment